First published: Wed Nov 01 2023(Updated: )
OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.<br>This advisory contains OpenShift Virtualization 4.12.8 images.<br>Security Fix(es):<br><li> golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325)</li> <li> HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)</li> <li> net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Virtualization |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:6248 is classified as important due to the potential for rapid stream resets that can exacerbate resource workloads.
To fix RHSA-2023:6248, you should upgrade to OpenShift Virtualization 4.12.8 images as recommended in the advisory.
RHSA-2023:6248 affects Red Hat OpenShift Virtualization.
No specific workaround is provided for RHSA-2023:6248; patching is recommended.
RHSA-2023:6248 addresses vulnerabilities in the net/http and x/net/http2 packages related to rapid stream resets.